Talk · 15 Jul 2026 · AppSec & DevSecOps Melbourne 2026
Shift Left vs AI: Who Owns the Future of AppSec?
Opened the conference in a formal debate, arguing the negative: shift-left security remains foundational, and AI strengthens it rather than replaces it.
AppSec and DevSecOps Melbourne 2026, run by Corinium at Crown Promenade, opened with a formal debate on the motion "Shift Left vs AI: Who Owns the Future of AppSec?". I drew the negative, which meant arguing that shifting security left remains foundational and that AI strengthens it rather than replaces it.
The case
AI has made detection dramatically better. Model-assisted triage and reachability analysis cut through the noise that made developers resent security tooling, and that deserves to be conceded properly rather than argued around.
But detection and prevention are different instruments. A runtime control raises a finding for a person to act on, under time pressure, in a live system, usually by someone who did not write the code. A pipeline control makes the decision once, in advance, at the moment of change, when the cost of being wrong is a failed build rather than an exposure window.
Runtime can alarm. Only the pipeline can refuse.
Current exploitation and remediation data point the same way: exploitation is getting faster while patching is getting slower, so a posture built on finding things and then fixing them is structurally behind. Regulators are also starting to price the security posture an organisation held before an incident, separately from how well it responded afterwards.
Where AI belongs
The pattern I argued for is short enough to fit on a slide: AI proposes, the gate disposes. Put models where a person was already reading output and they are transformative. Keep the refusal deterministic and legible, so it can be explained to an auditor and a developer in the same sentence.
Format
Five-minute opening statements, a moderated exchange, audience questions and a before-and-after audience poll. Preparation drew on a source-verified research brief covering the EU Cyber Resilience Act impact assessment, current exploitation and remediation data, and Australian privacy enforcement.